is thre a way to run a single query against yara t...
# general
v
is thre a way to run a single query against yara table with multiple sigfile's?
m
Yes, that should be possible
f
Have you tried using sig_group instead of sigfile? You can add multiple files collectively in a group and run a query with that sig_group. Though a group has to be defined in osquery.conf file.
☝️ 1
👍 1